erin 


| lJ ses B | OFFICE OF THE CHAIRMAN ere eke 


UNITED STATES 
COMMUNICATIONS 
SECURITY BOARD 


i6 September 1978 


TO; . DISTRIBUTION 
SUBJECT: National COMSEC Directive (U) 


The final draft of the new National COMSEC Directive is attached. 

This’ version incorporates the changes agreed at the USCSB (Former) meeting 
on 3 August 1978, and the results of separate discussion of issues raised 
in the Board meeting. This text will be discussed with the Executive 
Agent for COMSEC, and the Chairman, SSTP, prior to publication. It is 
intended that the attached draft become the official text unless changes 
are required by this coordination step; or if Members of the USCSB (Former) 
‘have additional comments. Please advise the Executive Secretary prior 

to 22 September if there are any additional comments. As discussed ; 
at the 3 August meeting, the Directive will be signed and issued by the 
‘Executive Agent for COMSEC. 
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RALD P. DINNEEN 
Chairman 
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NATIONAL COMSEC DIRECTIVE 


(U) References: (a) Executive Order 12036, U.S. Intelligence Activities, 
24 January 1978 


(b) PD/NSC-24, Telecommunications Protection Policy, 
16 November 1977 


(c) Executive Order 12065, National Security Information, 
28 June 1978 


(C) Executive Order 12036 and PD/NSC-24 (References (a) and (b)) 
designate the Secretary of Defense as the Executive Agent for Communications | 
Security (COMSEC) to protect all government-derived classified information and 
government-derived unclassified information which relates to the national 
security. "National security", as used in this Directive, is as defined 
in E.0. 12065 (Reference (c)), paragraph 6-104: "National security means the 
national defense and foreign relations of the United States." . 


(C) .The protection of national security information is a national 
responsibility, and the activities pertaining thereto must be organized and 
Managed to ensure maximum utilization of available resources to satisfy the 
nequirements of the National Security Council and the departments and agencies 
of the government. To ensure the coordination of the communications security 
activities of the several departments and agencies of the government, this 
directive establishes organizational relationships and delegates functions 
within the government for the discharge of the responsibilities assigned 
to the Secretary of Defense as Executive Agent for COMSEC. 


(U) For the purposes of this Directive, communications security is the 
protection of classified information and other information relating to 
national security resulting from the application of cryptosecurity, trans- 
mission security and emission security measures to electrical processing 
systems, and from the application of physical security measures to COMSEC 
information and material. These measures are taken to deny unauthorized 
persons information of. value which might be derived from the possession 
and study of telecommunications or electrical processing systems; or to 
ensure authenticity; or to provide jam resistance for telecommunications. 


1. (C) The Executive Agent for COMSEC. As prescribed in 
References (a) and (b), the Secretary of Defense, as the Executive Agent 

for Communications Security, is responsible for protecting government-derived 
classified information and unclassified information relating to the national 
security. As the Executive Agent, he shall: 


a. (U) Adhere to broad policy guidance promulgated by the 
National Security Council Special Coordination Committee through its’ ~ 
Special Subcommittee on Telecommunications Protection (SSTP). 


b. (C) Coordinate, as appropriate, with the Secretary of 
Commerce who has been designated as the government's Executive Agent for 
Communications Protection for government-derived unclassified information 
not related to national security, to reduce areas of overlap. . 
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2. (U) The National Communications Securit Committee (NCSC). 


a. (U) The National Communications Security Committee (NCSC) , 
hereinafter referred to as the Committee, is established to assist the . 
Executive Agent, COMSEC in the discharge of his responsibilities and to 
ensure a coordinated and effective national COMSEC effort. The Committee 
Shall operate in accordance with this directive and any other directives 
that may be issued by the Executive Agent. 


_. b. (U) The Committee shall be composed of one representative 
of each of the following: - 


(1) The Secretary of State 
(2) The Secretary of Treasury 
(3) The Attorney General 
(4) The Secretary of Defense 
(5) The Secretary of Transportation 
(6) The Secretary of Energy 
(7) The Secretary of the Arny 
(8) The Secretary of the Navy 
(9) The Secretary of the Air Force 
(10) The Director of Central Intelligence 
(11) The Director, National Security Agency 
c. (U) In addition to the above Committee aembership, 
representatives of the following are invited to participate as observers. 
They..may also be invited by the Chairman, NCSC to participate whenever- 
matters of direct interest to their respective departments or agencies are 
before ‘the Committee: © 
(1) The Secretary of Commerce’ 
(2) The Chairman, Joint Chiefs of Staff 
(3): The Administrator, General’ Services Administration 


(4) The Chairman, Federal Communications Commission 


(5). The Manager, National Communications System 
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(6) The Director, Defense Communications Agency 

(7) The Director, Defense Intelligence Agency 

(8) The Director, Defense Logistics Agency 

(9) The Director, Federal Emergency Menaapmert Agency 


d. (U) Under the authority of the haituan’ NCSC, it shall 


‘be the prepOnee re ne, of the Committee to: 


(1) Act in support of the Executive Agent, COMSEC. 


(2) Establish broad COMSEC objectives, policies and 
ene procedures she beecutine bgenty MSE ie sooorisae K 


(3) Develop Seavdineved interagency recommendations for 
the Executive Agent, COMSEC's approval, when. required. 


; (4) Review annually for the Executive Agent the COMSEC 
Status and objectives of all departments and agencies and make recommendations 
for cCSe: applications. 


(5) Establish a national COMSEC issuance system for 
promulgating policies and for issuing COMSEC guidance and information of 
government-wide interest. Objectives and policy issuances will be signed 
by the Executive Agent after coordination with the Chairman, SSTP. 


(6) Provide COMSEC guidance in accordance with approved 
procedures to U.S. Departments and Agencies in their relations with foreign 
governments, international organizations, and private industry. 


e. (U) The Committee shall make recommendations to the 
Executive Agent. on Committee membership and shall establish procedures and 


. membersute eriteria for pons teeh tag membership changes. 


£. (U) The Committee shall meet at the invitation of the 
Chairman or request of any member. A minimum of two formal meetings shall 
be held annually and the presence of a majority of the members shall 
constitute a quorum. : 


g- (U) The Committee shall reach decisions by majority vote. 
In the event of a tie, the Chairman shall cast a deciding vote. The 
Director, National Security Agency shall have no vote in matters involving 
appeals fron his ‘own decision. In the event the Committee votes and reaches 
a decision, any dissenting member of the Committee may appeal. from such a 
decision. Such appeal must be made within 15 days to the Executive Agent 
for COMSEC.. In the event that the Committee votes and fails to reach a 
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decision, any member of the Committee May appeal to the Executive Agent for 
COMSEC and such appeal must be made within 15 days of the inconclusive vote. 
In either event, the Executive Agent shall review the vote and reach a 
decision. If the subject of the appeal is in the nature of an emergency, 
the Executive Agent will determine action to be taken pending outcome of 

the appeal. Action by the Executive Agent does not preclude referral to 
the SSTP or higher bodies. Appeal by the representative of any component 

. o£ the Department of Defense shall be filed only with the approval of the 
Secretary of Defense. 


h. (U) The Chairman may invite any department or agency not 
represented to participate in matters of direct interest to such a depart-_ 
ment or agency. Such a department or agency may also request consideration 
of a matter by the Committee. 


i. (U) Departments or agencies not represented on the 
Committee may appeal from decisions of the Committee in the manner prescribed 
for departments and agencies represented on the Committee. 


3. (C) Chairmanship of the National Communications Securit 
Committee (NCSC). The NCSC shall be chaired by the representative of ‘the 
Secretary of Defense, the Assistant Secretary of Defense for Communications, 
Command, Control and Intelligence (ASD(C°I)). He is responsible for: 

‘a. (U) Establishing procedural arrangements for the 
execution of his assigned functions. 


b. (U) Maintaining liaison with the Office of the Secretary 
of Commerce who is the Executive Agent of the government for protection of 
communications not related to national security, 


c. (U) Keeping the Executive Agent, COMSEC, informed on 
significant current COMSEC matters in the Committee. 


x: 


~ 


d., (U) Establishing procedural arrangements for the discharge ’ 
of staff responsibilities of the Executive Agent, COMSEC. 

@.° (U) Requesting such reports, information and. assistance 
from governmental agencies as May be necessary. 


4.. (C) The National Communications Security Committee Secretariat. 


a. (U) There is hereby established a National Communications 
Security Committee Secretariat that shall be responsibie to and function 
under the direction of the Chairman, NCSC. This Secretariat shall provide 
the necessary staff assistance and services for the conduct of Committee 
business, 
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b. (U) The Director, NSA, will provide a Secretariat, 
including an Executive Secretary who will be approved by the Chairman, 
and all resources required for this office, including space, equipment 
facilities, personnel, and administrative support. 


ce. (C) In carrying out its functions, the Secretariat shall: 


(1) Serve as the staff central point of contact for NCSC 
functions, bye 


(2) Coordinate Committee matters as necessary with 
Committee members and other government departments and agencies. 


(3) Provide for the receipt and processing of certain 
Executive Agent, COMSEC and Committee correspondence. 


(4) Maintain active liaison with: The Executive Secretary 
SSTP for the exchange of information and advice and to keep the Executive 
Secretary SSTP informed on significant COMSEC matters in the NCSC; the 
Office of the Assistant Secretary of Commerce for Telecommunications and 
Information; the Executive Secretary for the National Foreign Intelligence 
Board; and other departments and agencies. 


(5) Be responsive to the requirements of Committee 
fhembers oud serve as the direct contact with the NCSC staff members. 


5. (C) The Director, National Security Agency. As piesceined in 


reference (a), the Director, NSA, is responsible for executing the responsi- 
bilities of the Secretary of ‘Defense as Executive Agent for Communications 
Security. These responsibilities for the purpose of this Directive are set 
forth below. In the execution of these responsibilities, he shall fulfill 
requirements of the various departments and agencies” of the Government. 


a. (U) Prescribe or approve all cryptographic ‘systems and 
techniques used by or on behalf of the government to safeguard national 
security and national security-related telecommunications and electrical 
' processing systems from exploitation or disruption; or to ensure authenticity. 
Included are the doctrine, standards and procedures governing their operation, 
use, modification or removal from use, and the application of compromising 
emanations suppression techniques and physical security measures to protect 
such systems and techniques. 


b. (U) Initiate research and development needed to fulfill 
confirmed requirements for cryptographic equipment to be used to safeguard 
national security and national security related telecommunications and 
electrical processing systems; or to advance communications security 
technology, including techniques, protective measures, standards for 
controlling compromising emanations, and basic or applied cryptographic 
and cryptanalytic research. When mutually agreed, the Director, NSA, may 
delegate authority to conduct specified cryptographic R&D ‘Projects. 
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; ce. (C) Establish and maintain a national COMSEC assessment 
program to advise the Executive Agent, the Committee and other federal 
departments and agencies on the vulnerability to and evidence of hostile 
exploitation of telecommunications and electrical processing systems; and 
report to the National COMSEC Committee in Support of the Committee's 
Annual Report, 


d. (U) Generate and produce COMSEC aids, including all forms 
of keying material, act as the central procurement authority for TSEC- 
homenclated equipments and design controlled spare parts, maintain a Central 
Office of Record (COR). When mutually agreed, DIRNSA may authorize federal 
departments and agencies to produce specified TSEC-nomenclated equipments 
and cryptomaterial in accordance with technical and security criteria 
prescribed by Director, NSA. . 


e. (C) Conduct technical COMSEC liaison with the appropriate 
organizations of foreign governments and international organizations concerned 
with such matters, oer 


f. (U) Develop for publication by the NCSC timely and 
coordinated long-range National COMSEC Plans, to include consideration 
of equipment research, dev lopment and application, threat projection 
and security requirements. a er (ee 4 


'\g. (U) Provide technical guidance and support for COMSEC 
education and training programs. 


h. (C) Obtain information needed to maintain an overview 
of COMSEC resource programs, to assure optimum utilization, and to conduct 
assessments of the COMSEC protection provided to national security or 
national security related information. a 


i. (C) Collaborate with departments and agencies in order to: 


. (1) Develop basic hnoncryptographic COMSEC design criteria 
_ for telecommunications.and electrical processing systems, including command ~ 
and control systems for weapons and space vehicles, determine the level of 
protection provided by a specific system, and advise and assist the cognizant 
department and agency, . : BER a ox 


(2) Assist in defining requirements for COMSEC equipments 
and systems. ; a, * . 


(3) Formulate doctrine and standards for the application 
of COMSEC techniques to computer systems, _ 


. 


In accordance with responsibilities assigned in refs. (a) and (b). 
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(4) Assist in the formulation of principles and the 
development of techniques for communications cover and manipulative 
. communications deception, and in the preparation or review of the COMSEC 
elements of these programs. 


(5) Assist in the identification of requirements for 
vulnerability assessments; assist in the identification of COMSEC 
surveillance and analysis resources to conduct vulnerability assessment 
missions. 


(6) Assist in the identification of requirements for 
COMINT threat assessments; establish and maintain a central data base 
containing all source information on all hostile COMINT threats to U.S, 
government telecommunications and electrical processing systems; identify 
analytic resources to conduct threat assessments, 


(7) Prescribe procedures for reporting and evaluating 
COMSEC insecurities; and doctrine and procedures to protect COMSEC 
information. : ee: 


(8) Prescribe standards for federal departments aad 
agencies Central Office of Record (COR) functions. 


_ (9) Establish policies and procedures for the conduct 
of an interdepartment/agency loan program and the reuse of excess equipment. 


; 6. (U) The Heads of Departments and Agencies of the Government. 
The Heads of all Departments and Agencies of the Federal Government shall 
organize and conduct their COMSEC activities as they see fit, subject to 
the provisions of law, directives of the President and the National Security 
Council, this.Directive, and documents in the National COMSEC Issuance System, 
Nothing in the directive shall relieve the heads of the individual departments 
and agencies of their responsibilities for executing all measures’ required to 


_ assure the security of classified and unclassified national security infor- 
mation and the control of compromising emanations. 


7. (U) Disclosure Privileges. Nothing in this directive shall 
be construed to give the Committee, any of its members, and the Executive 
Agent, or the Director, NSA, the right to inspect any department or agency 
without approval by the head thereof, Departments and agencies shall not 
be required to disclose to the Committee, any of its members, the Executive 
Agent, or the Director, NSA, the contents of any official communications 
concerning its activities, if, in the opinion of the head of the departnent 
or agency, the disclosure would be contrary to the national interest. 

. 8. (C) Exemption. The communications conducted by the Central 
Intelligence Agency in the performance of functions described in NSCID No. 5 
are specifically exempted from this Directive. 
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